Establish Connection 


Wireless Wired 
Target is wireless-capable Hacker can jack in 
&in range or tap cable carrying data 


Hacker can locate Target traffic 


Defeat Firewall 


Spoofing 

Infosec Test 

Timeframe: 10 minutes 

Modifiers: Spoof quality, Firewall quality, 
Security priveleges (-20), Admin priveleges 
(-30) 

Note: Privilege level depends on traffic being 
sniffed. 


ECLIPSE PHASE HACKING CHEATSHEET 


Mesh 
Target online 
Hacker knows mesh ID 


Standard Hacking 
Infosec Test 
Timeframe: 10 minutes 


by voidstate 


Feedback, corrections and suggestions welcome to rpg@voidstate.com 


Note 


At any time a hacker will have a connection type, status and privelege 
level. A system will be monitored or unmonitored, and have an alert level. 


Modifiers: Exploit quality, Firewall quality, Security 


priveleges (-20), Admin priveleges (-30) 


System Monitored? 


+4 


No 
Normal Exceptional 
success success 


Yes 


| | 


Opposed Infosec Test 


Modifiers: Exploit quality, Firewall quality, Security priveleges (-20), Admin priveleges (-30) 


r Both fail 


Hacker wins with excellent 
success, Defender fails 


Hacker succeeds, 
Defender fails 


Hidden Status 

Hacker does not appear in 
logs, has admin priveleges 
and has +30 to subvert 
system - but not defend 
against countermeasures. 


Covert Status 


the system at current 
privelege level. 


User Priveleges 
No penalty to defeat 
firewall 


Security Priveleges 
-20 to defeat firewall 


Upgrading Status 


Hacker appears in logs as a 
legitimate user. May use 


Both succeed 


Spotted Status 


privelege level. 


System goes on Passive 
Alert (-10 to Hacker's 


actions). 


System may engage 
Passive Countermeasures. 


Locate Intruder 
Opposed Infosec test 


Admin Priveleges 
-30 to defeat firewall 


Win downgrades Hacker 
to Locked Status. 


Hacker may use the 
system at current 


Brute-Force Hacking 

Opposed Infosec Test 

Timeframe: 1 minute 

Modifiers: +30 brute-force modifier, Exploit quality, 
Firewall quality, Security priveleges (-20), Admin 
priveleges (-30) 


Roll again on 
Hacker's next 
action 


Hacker fails, 
Defender succeeds 


Locked 

Hacker may use the 
system at current 
privelege level. 

System goes on Active 
Alert, inflicting a -20 to 
Hacker's actions). 

System may launch Active 
Countermeasures. 


Passive Countermeasures 


Re-Authenticate 

At start of next Action 
Turn, Hacker must suceed 
at an Infosec test (with -10) 
or downgrade to Locked 
status 


Reduce Priveleges 
Protect logs from standard 
users’ access 


Active Countermeasures 


Counterintrusion 


Attack Hacker's ecto/mesh 


inserts or PAN. 


Reboot/Shutdown 
Complex action. 
Shutdown takes between 


Lockout 
REquires security or admin 
priveleges. 


Covert status 


Spotted status 


Locked Status 


Infosec test Opposed Infosec test 
Excellent success improves Win & Excellent success 
status one step improves status one step 


Downgrading Status 


Hacker scores critical 
failure 

Status downgrades to 
Locked status 


Hacker scores severe 
failure 

Status downgrades one 
step 


AR Illusions 

Must have hacked ecto 
/mesh inserts. 

Pre-made illusions pose 
-10 to -30 penalty to 
identify. 

Improvised illusions grant 
+10 to +30 to identify. 
Illusions grant -10 to -30 to 
target's Perception or 
other actions. 


Use the System 

Once past the firewall, the 
Hacker may freely use any 
part of the system they 
have priveleges for. 

Other parts require an 
unopposed Infosec test 
with between a 0 and -30 
penalty. Spotted status 
imposes a further -10 to this 
roll. Locked imposes -20. 


Not possible 


Crash Software 

Complex action. 

Requires Infosec test 
(opposed if crashing an Al, 
AGI or infomorph). 

2 tests needed to crash 
Als, 3 to crash AGIs and 
infomorphs. 


Backdoor 

Requires Infosec test 
(opposed if system 
monitored). 

Then requires Program- 
ming test (-20 for Security 
priveleges or -30 for 
admin). 

Once in place, Hacker may 
bypass firewall without a 
test. 


Requires tracking. See p. 
251-2 


Trace 
Track Hacker's physical 


location through mesh ID. 


Eliminate Traces 
Complex action. 
Requires Infosec test 
(opposed if system 
monitored). 


Opposed Infosec test (with 


1 turn and 1 minute, after 


Hacker suffering -20). 
Success ejects Hacker from 
the system. 


which Hacker is ejected. 
Reboot takes the same. 


Wireless Termination 
Complex action. 

Takes 1 turn, after which 
all wireless connections 
are severed, ejecting 
wireless or mesh 
connected Hackers. 


Scripting 

Creating script requires 
Programming test. Max 
actions = (programming / 
10) 

Loading script requires 
Infosec test (opposed if 
system monitored). 
Programmer's Infosec 
used for script’s actions. 


Hacking VPNs 

Hacker must first hack a 
device connected to the 
VPN, then hack the VPN. 


